nTimetools Logo

nTimetools

0
Free
Visit Website

nTimetools is a suite of console tools developed to work with timestamps in Windows. nTimetools comprises 2 tools that allow both forensic analysts as well as red teamers to modify and verify file timestamps up to 100-nanosecond precision. nTimeview allows forensic analysts to view the MACB timestamps of files on a live system. It uses the undocumented NtQueryInformationFile API. As such, it works on NTFS/FAT and even mapped drives. It does not require privileged access. nTimestomp allows red teamers to timestomp MACB timestamps of files with 100-nanosecond level precision. Forensic analysts are usually taught to spot 0s in the millisecond position as evidence that timestomping has occurred.

FEATURES

ALTERNATIVES

A library and tools for accessing and analyzing Linux Logical Volume Manager (LVM) volume system format.

Magnet ACQUIRE offers robust data extraction capabilities for digital forensics investigations, supporting a wide range of devices.

Powerful tool for searching and hunting through Windows forensic artefacts with support for Sigma detection rules and custom Chainsaw detection rules.

A library to access and manipulate RAW image files.

A collection of PowerShell modules for artifact gathering and reconnaissance of Windows-based endpoints.

A repository containing material from a talk on sub-domain enumeration techniques

A tool for creating compact Linux memory dumps compatible with popular debugging tools.

A forensics tool for tracking USB device artifacts on Linux machines.

PINNED